Return-Path: Delivered-To: apmail-roller-user-archive@www.apache.org Received: (qmail 3074 invoked from network); 13 Jan 2008 15:56:59 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 13 Jan 2008 15:56:59 -0000 Received: (qmail 136 invoked by uid 500); 13 Jan 2008 15:56:48 -0000 Delivered-To: apmail-roller-user-archive@roller.apache.org Received: (qmail 115 invoked by uid 500); 13 Jan 2008 15:56:48 -0000 Mailing-List: contact user-help@roller.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@roller.apache.org Delivered-To: mailing list user@roller.apache.org Received: (qmail 106 invoked by uid 99); 13 Jan 2008 15:56:48 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 13 Jan 2008 07:56:48 -0800 X-ASF-Spam-Status: No, hits=2.0 required=10.0 tests=HTML_MESSAGE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: local policy) Received: from [89.207.58.70] (HELO mx5.rte.ie) (89.207.58.70) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 13 Jan 2008 15:56:24 +0000 Received: from unknown (HELO CLUSTER-XCH1.RTEGROUP.IE) ([10.100.101.60]) by mx5.rte.ie with ESMTP; 13 Jan 2008 15:56:28 +0000 X-MimeOLE: Produced By Microsoft Exchange V6.5 Content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C855FC.DA0DB03E" Subject: RE: restrict logins to IP range Date: Sun, 13 Jan 2008 15:56:25 -0000 Message-ID: X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: restrict logins to IP range Thread-Index: AchUyrXzEid2/46CQyqMZNMCA0x0LgBMQoFV References: <8fb9ac720801111924je0cd96ag2a5523b92c2a7612@mail.gmail.com> From: "Moylan John" To: , X-Virus-Checked: Checked by ClamAV on apache.org ------_=_NextPart_001_01C855FC.DA0DB03E Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi, My LocationMatch regex got removed somewhere on route to the mailing list. = I had been trying to restrict access to login.do only. However, this is not easy to do because security_check.jsp does a redirect = and Apache thinks all requests are coming from internal addresses. The best= solution I found was to have two virtualhosts, one listening on port 80 th= e other on port 443. The port 80 host is available to outside users via the firewall but uses mo= d_rewrite conditions to proxy only certain pages. The virtual server on port 443 is made available to internal users only, ag= ain via the firewall. The port 443 host has the entire roller application m= ounted and encrypts account credentials using mod_ssl. J -----Original Message----- From: Dave [mailto:snoopdave@gmail.com] Sent: Sat 1/12/2008 03:24 To: user@roller.apache.org Subject: Re: restrict logins to IP range =20 On Jan 8, 2008 10:14 AM, john moylan wro= te: > I'm using Roller 3.1 with Apache 2.0, JBoss 4.05 and mod_jk on Linux. > I am trying to restrict access so that users can only login from a single= ip range. > I have tried using the LocationMatch directive in apache, eg: > Order Deny,Allow > Deny from All > Allow from 192.168. > > But this does not seem to have any effect. > > Can anyone explain the best way to restrict logins to certain IP ranges? I don't know enough Apache HTTPD conf to help. That's probably a question for the HTTPD mailing list. But, if you deny access from all like that you'll be completely preventing access, not just preventing logins. Is that really what you want to do? - Dave *********************************************************** The information in this e-mail is confidential and may be legally privilege= d=2E It is intended solely for the addressee. Access to this e-mail by anyone el= se is unauthorised. If you are not the intended recipient, any disclosure, copying, distribution, or any action taken or omitted to be taken in relian= ce on it, is prohibited and may be unlawful. Please note that emails to, from and within RT=C9 may be subject to the Fre= edom of Information Act 1997 and may be liable to disclosure. ************************************************************ ------_=_NextPart_001_01C855FC.DA0DB03E--